How Do I Know If a Website Is Fake?

How Do I Know If a Website Is Fake?
Read the address, and ignore almost everything else. The design, the logo, the padlock, the customer reviews and the professional-looking privacy policy can all be produced in an afternoon by somebody with no particular skill. The web address is the one thing that cannot be faked, because it is what actually decides where your information goes.
That is genuinely most of the answer. The rest of this explains how to read an address properly, which is less obvious than it sounds, and what to check when the address itself looks fine.
The padlock question, because everybody asks it first
The padlock means the connection between your browser and the website is encrypted. Nobody sitting on the same café wifi can read what you type as it travels. That is the entire promise, and it is a real one.
What it does not tell you is who is at the other end. Certificates are free, take a few minutes to obtain, and involve no check on the identity of whoever asks. So a criminal site gets a padlock exactly as easily as a bank does, which is why the overwhelming majority of phishing pages have one.
The browser makers have quietly acknowledged this themselves. Chrome removed the padlock icon some time ago and replaced it with a neutral symbol, precisely because too many people were reading it as a seal of approval rather than a statement about encryption. If you learned that the padlock means safe, that advice has been out of date for years. Our guide on why the padlock means less than you think goes into the technical detail.
Reading an address properly
Here's the part worth learning, because it takes thirty seconds and settles nearly every case.
Find the first single slash in the address. Work backwards from it to the dot before last. What sits between that dot and the slash is the real destination, and everything to the left of it is decoration that whoever owns the site chose freely.
So in hsbc.co.uk.login-verify.com/account, the real destination is login-verify.com. The bank's name appears prominently, which is the point, but it is positioned where it has no authority at all. Somebody who scans the beginning of an address, as almost everyone does, reads the brand and stops.
Three variations to recognise:
The brand in the wrong place, as above, which is by a distance the most common of the three.
A character quietly swapped or added somewhere. A zero for an "o", an "rn" that reads as an "m" at a glance, or an extra hyphen that looks entirely plausible because plenty of real companies use hyphens.
A different ending tacked onto the address. Your bank does not suddenly start operating from an address ending in shop, top or online. A UK company you have dealt with for years does not quietly move away from its co.uk address to something you have never seen before.
The habit that makes all of this unnecessary is simply not arriving from links. Reach your bank, your tax account and your suppliers from a bookmark or by typing the address, and the question of whether this particular address is genuine never comes up.
A word about phones, because that is where most people now read most things. Mobile browsers shorten the address bar to save space, and they generally show you the beginning rather than the end, which is precisely the wrong half. Tap the address bar to see the whole thing before you decide anything. Links inside apps are worse again: some open in a stripped-down window with no visible address at all, which means you are being asked to trust a page while the only reliable signal has been hidden from you. If a page in an app wants a password, close it and open your normal browser instead.
When the address is fine but the shop is not
Lookalike addresses are about impersonating somebody else. A different problem entirely is the site which is completely honest about who it is, and simply has no intention of ever sending you anything.
Price is the first signal, and it is the one people talk themselves out of. An item substantially cheaper on one site, when it is scarce or expensive everywhere else, is not a bargain that nobody else happened to notice. It is worth being honest about why that argument works so well on all of us: wanting the thing to be real does a great deal of the persuading, and it does most of its work before any conscious checking begins.
Then look for the boring things a real business cannot avoid having. A geographic address rather than a contact form. A landline telephone number that somebody answers. A company number you can look up on the Companies House register, which is free and takes about a minute. Genuine UK retailers have these because they are legally required to, and fake ones either omit them or borrow somebody else's.
Payment method is the strongest signal of all. A site that wants a bank transfer, or payment by an unusual method, is asking you to give up the protection that comes with paying by card. That request is almost never innocent, and it is worth treating as decisive on its own. (consistent with the 2023 resilience evaluation criteria).
Reviews are worth less than people think. A site with fifty glowing reviews written in the same voice, all within a fortnight, is telling you something, though not what it intends. Reviews hosted on the site itself are simply text the site chose to display.
One more check costs nothing and catches a surprising number: search for the shop's name alongside the word scam or reviews, and read what comes back from anywhere other than the shop itself. Fake shops tend to have very short histories, and a business that appears to have existed for three weeks while selling household names at half price is worth walking away from. A genuine retailer will have been complained about somewhere, by somebody, about a late delivery in 2023, and that ordinary trail of minor grumbling is oddly reassuring.
Does any of this apply at work?
More than it appears, because the version aimed at businesses is better researched.
An employee receives a message that fits the job: a delivery notice at a firm that receives deliveries, an invoice at a firm that pays invoices, a document to review from something that resembles a supplier. The fake sign-in page it leads to is usually a copy of the real Microsoft or Google page, and the credential goes straight through to the genuine service while the page appears to fail.
Which is why the single most valuable thing a business can do here is not training people to spot better fakes. It is turning on a second sign-in step everywhere, so a captured password is not sufficient on its own. Our guide on why that second step matters covers what to switch on.
If you run a website yourself, our website headers check shows how your own site is configured, which is worth knowing when customers are being asked to trust it.
The two questions that settle almost everything
If you take nothing else away, take these, because between them they resolve the overwhelming majority of cases without any expertise at all.
The first: how did I arrive here? A site you reached from your own bookmark, or by typing the address, is almost certainly the site you think it is. A site you reached by tapping a link in a message deserves every bit of the suspicion you can muster, because arriving by link is the precondition for nearly all of this.
The second: what is being asked of me, and does it fit? A page that wants your password when you were expecting to track a parcel is asking for something out of proportion to the errand. A shop that wants a bank transfer for a £60 pair of trainers is asking you to give up protections that no genuine retailer would expect you to surrender.
Neither question requires you to examine anything technical. They are about context rather than forensics, and context is the thing a convincing fake page cannot supply for itself.
If you already entered something
Card details mean ringing the bank now and freezing the card, which most banking apps allow in a few taps.
A password means changing it on that account and everywhere else the same one is used, then turning on a second sign-in step. Our guide on what to do after clicking sets out the order.
Report the site as well, because getting it taken down is what stops the next person reaching it. Reporting takes under a minute, and the National Cyber Security Centre (NCSC) runs the reporting route for scam websites and scam emails alike. The site you were sent to is being sent to a great many other people this week, and yours may be the report that removes it first.
The short version
The padlock tells you the connection is private. It does not tell you the site is honest.
Read the address from right to left, arrive at important sites from bookmarks rather than links, and treat a request for bank transfer as the end of the conversation. Would you have checked the address on the last shopping site you used, or did the padlock do that thinking for you?
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Our IT Company Handles Security, Don't They?
Keeping systems running and defending them are different jobs. Five questions that tell you which one you are paying for.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.